Splunk Search

Unable to break events using multikv?

sarvesh_11
Communicator

alt textHi Splunkers,
Please find attached image, this is the way i am getting my data.
My desired format is :

Hostname | Microsoft .NET Framework 4.5.1 | Microsoft POS for .NET 1.12 | JAVA 8 Update 60 | UniversalForwarder | - -------
hostA | 4.5.50938 | 1.12.1296 | 8.0.600 | 7.2.5 | - -------

My procedure is, to break the events with multikv and then use transpose.

But multikv is not functioning as desired.

TIA,

0 Karma
1 Solution

to4kawa
Ultra Champion
| rex mode=sed "s/\s\s+/,/g"
| multikv forceheader=2

try this.

View solution in original post

vnravikumar
Champion

Hi

Attachment is missing.

0 Karma

sarvesh_11
Communicator

hi @vnravikumar ,

Updated

0 Karma

to4kawa
Ultra Champion
| rex mode=sed "s/\s\s+/,/g"
| multikv forceheader=2

try this.

sarvesh_11
Communicator

Thanks @to4kawa

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...